From: Paulo Alcantara <pc@manguebit.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, linux-cifs@vger.kernel.org
Subject: [GIT PULL] smb client fixes for 7.3-rc3
Date: Thu, 10 Sep 2026 12:45:41 -0300 [thread overview]
Message-ID: <bb769b6f6f976d75cbfca3ed00556bde@manguebit.org> (raw)
Linus,
Please consider pulling these smb client fixes for v7.3-rc3. They
address file type corruption in reparse point handling, uid/gid
ownership mapping bugs, heap overflows in DACL rewriting, reference
count leaks, a DFS use-after-free and hardening of legacy smb1 input
validation. All fixes are for stable.
Thanks,
Paulo
----------------------------------------------------------------
The following changes since commit 89a312991dc6e638a36adc43ccb91dbc25504c04:
Merge tag 'cifs-fixes-7.3-rc2' of https://git.manguebit.org/linux (2026-09-01 13:37:14 -0700)
are available in the Git repository at:
https://git.manguebit.org/linux.git tags/cifs-fixes-7.3-rc3
for you to fetch changes up to cb26524ef4ac28fcfa554c0656e8dc412c38a8ff:
smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (2026-09-09 22:06:05 -0300)
----------------------------------------------------------------
smb client fixes for v7.3-rc3
A batch of bug fixes for the smb client:
- File type corruption fixes in reparse point handling: setting S_IFMT
bits without clearing the existing type first corrupted the file mode
(e.g. S_IFREG | S_IFCHR == S_IFLNK). Fixed in the WSL, POSIX and
native symlink reparse parsers. Also fixes an uninitialized SID
structure in the POSIX readdir path when parsing fails.
- Ownership mapping fixes: forceuid/forcegid mount options were
ignored in several code paths (SID-to-id mapping, WSL extended
attributes, POSIX extensions getattr), allowing an untrusted server
to dictate local file ownership despite explicit mount overrides.
- Heap overflow and overflow fixes in DACL rewriting: replacing short
SIDs with long ones could overflow the DACL buffer, and the u16
accumulator for DACL size could wrap around with enough ACEs.
- Reference count leak fixes in oplock break and deferred close:
duplicate oplock breaks on a queued work item leaked a
cifsFileInfo reference, and deferred close had a similar leak when
requeueing a running work item. Both cause busy-inode oopses on
unmount.
- DFS superblock use-after-free fix: the iterator callback stored a
raw superblock pointer without pinning it, racing with automount
expiry.
- One-byte slab OOB read in the native symlink parser when handling
share-root relative paths.
- Hardening of legacy SMB1 input: reject userspace-crafted
cifs.idmap key descriptions that bypass kernel origin checks, and
validate DataOffset in CIFSSMBRead() to prevent heap info
disclosure from a malicious server.
- DFS cache fix: defer metadata updates until target copying
succeeds to prevent partial-state cache entries on allocation
failure.
----------------------------------------------------------------
Aohan Mei (1):
smb: client: reject userspace cifs.idmap descriptions
Bjoern Doebel (4):
smb: client: avoid leaking refcount in cifs_queue_oplock_break()
smb: client: avoid leaking refcount when cifs_sb_tlink() fails
smb: client: fix heap overflow in DACL owner/group rewrite
smb: client: fail DACL rewrite when the new DACL exceeds 64K
Diego Oliva (2):
smb: client: reject short READ responses in CIFSSMBRead()
smb: client: reject out-of-bounds DataOffset in CIFSSMBRead()
Fan Wu (1):
smb: client: fix cifsFileInfo reference leak in deferred close
Fredric Cover (1):
smb: client: fill cache fields after populating cache in copy_ref_data()
Karl Mehltretter (1):
smb: client: pin DFS superblock in iterator callback
Paulo Alcantara (8):
smb: client: fix uid/gid override in getattr with posix extensions
smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid
smb: client: fix WSL reparse point uid/gid override
smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()
smb: client: fix file type corruption in wsl_to_fattr()
smb: client: fix file type corruption in posix_reparse_to_fattr()
smb: client: fix file type corruption in cifs_reparse_point_to_fattr()
smb: client: fix one-byte OOB read in smb2_parse_native_symlink()
fs/smb/client/cifsacl.c | 95 ++++++++++++++++++++++++++++++++---------------
fs/smb/client/cifssmb.c | 26 ++++++++++---
fs/smb/client/dfs_cache.c | 18 ++++-----
fs/smb/client/file.c | 22 ++++++++---
fs/smb/client/inode.c | 17 ++++++---
fs/smb/client/misc.c | 24 ++++++------
fs/smb/client/readdir.c | 17 +++++++--
fs/smb/client/reparse.c | 33 ++++++++++------
fs/smb/client/trace.h | 1 +
9 files changed, 172 insertions(+), 81 deletions(-)
next reply other threads:[~2026-09-10 15:45 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 15:45 Paulo Alcantara [this message]
2026-09-10 21:52 ` pr-tracker-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bb769b6f6f976d75cbfca3ed00556bde@manguebit.org \
--to=pc@manguebit.org \
--cc=linux-cifs@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®